The Game Rating and Administration Committee (GRAC) has strengthened its ability to investigate reports that disclosed probability information may not match the probabilities actually applied within a game.
Many developers assume that their probability settings are accurate because the values were verified before launch. However, a compliance review may examine not only the configured probability, but also the disclosed tables, server logs, change history, and actual transaction data.
The five-stage framework below summarizes the investigation process publicly described by Korean authorities. The exact procedure may vary depending on the evidence, technical complexity, and nature of the suspected violation.
A case may begin through a user report, regulatory monitoring, or another source indicating that the disclosed probability may be inaccurate.
GRAC initially examines whether the report contains a sufficiently objective basis for further review.
Relevant information may include:
A low acquisition rate by itself does not automatically establish that a probability is false. GRAC first considers whether the available information provides a reasonable basis for additional verification.
After the preliminary review, GRAC determines whether further investigation is necessary.
If there is no objective basis for suspicion, the case may be closed or the complainant may be asked to provide additional information.
If further verification is warranted, GRAC may request relevant materials from the game developer. Depending on the case, these materials may include:
The scope of the request will depend on the suspected discrepancy and the structure of the probability system.
Where technical verification is required, GRAC may analyze the submitted data and obtain assistance from an external statistical or technical analysis institution.
The analysis may compare:
This process is particularly important for systems involving pity mechanics, dynamic weighting, multi-stage rewards, limited pools, or probability changes based on previous outcomes.
An external analysis does not rely solely on the developer’s explanation. The relevant data may be statistically reviewed to determine whether the actual results and system configuration are consistent with the disclosed probability.
After reviewing the available evidence and technical analysis, the authorities assess whether a disclosure violation may have occurred.
The findings may involve different types of issues, including:
Where a violation of Korea’s probability disclosure requirements is identified, corrective procedures under the Game Industry Promotion Act may follow. These can include a corrective request, corrective recommendation, or corrective order, depending on the circumstances and whether the developer implements the required changes.
If there are indications that consumers were misled by false or deceptive probability information, the matter may also be reviewed for referral to the Korea Fair Trade Commission (KFTC).
Referral to the KFTC and user damage-relief proceedings are not automatic in every case.
Depending on the nature and seriousness of the suspected conduct, the Ministry of Culture, Sports and Tourism or GRAC may coordinate with the KFTC or another competent authority.
The KFTC may independently assess whether the conduct violates the Act on the Consumer Protection in Electronic Commerce or other applicable consumer-protection laws. GRAC’s technical findings can provide relevant information, but the KFTC makes its own decision regarding investigation and enforcement.
When a user has suffered financial damage from a missing or false probability disclosure, GRAC’s Probability-Based Item Damage Relief Center may also review the claim.
Depending on the case, the user may receive:
The regulatory investigation and user-relief process may be connected, but they remain legally distinct procedures.
The most significant part of the investigation process is the ability to compare multiple sources of technical data.
A probability shown correctly on a website does not establish compliance if a different value was applied by the server. Likewise, a correctly configured server value may not prevent a violation if the value displayed to users was missing, outdated, or incorrectly calculated.
Technical analysis may identify discrepancies between:
The issue is therefore not limited to whether the probability algorithm was intentionally manipulated. An implementation mistake, delayed webpage update, localization error, or incorrect decimal calculation may also create compliance exposure.
A KFTC referral does not mean that a violation has already been finally established. The KFTC conducts its own review under the laws within its jurisdiction.
However, false or misleading probability information may expose a developer to risks beyond GRAC’s corrective procedures.
Depending on the facts, these risks may include:
Korean authorities have previously applied the Electronic Commerce Act to cases involving probability information that was falsely disclosed or omitted in a manner that could mislead consumers.
Developers should be able to demonstrate how each publicly disclosed value was generated and confirm that it matched the probability actually applied during the relevant service period.
Server configuration, in-game UI, official website tables, and regulatory materials should use the same verified probability data.
Avoid manually entering the same values into multiple systems whenever possible.
Maintain records showing:
These records should make it possible to reconstruct the probability applied on a specific date.
Logs should allow the relevant probability event to be identified and reviewed.
Depending on the system, this may require recording:
The appropriate retention period and data scope should be reviewed with technical, privacy, and legal teams.
Pity systems, escalating rates, limited pools, and multi-stage reward structures require additional verification.
Testing should confirm that:
A backend change should not become effective before the related probability information is updated through the applicable user-facing channels.
Review the in-game UI, official website, notices, localized pages, and update history as part of a single release checklist.
Most probability disclosure violations do not necessarily arise from deliberate manipulation. They may result from fragmented data management, manual calculations, deployment delays, or a lack of ownership between engineering, live operations, localization, and compliance teams.
Once a formal investigation begins, the developer may need to reproduce historical probability settings and explain how those settings were disclosed to users.
The most effective response is therefore to build audit readiness into the probability system before a complaint or regulatory request occurs.
Ask your team:
TheGameAgent helps overseas developers review probability disclosures, technical evidence, update procedures, and responses to Korean regulatory inquiries.
For additional guidance, read our Korea Probability Disclosure Compliance: 5 Essential Q&As.
Is your company’s Korean compliance framework ready for the next regulatory request? Contact TheGameAgent for a practical review of your domestic agent structure and probability disclosure process.
This article provides general information and does not constitute legal advice. Regulatory requirements and administrative guidance may change, so developers should confirm the latest rules before launch.

A step-by-step guide for global developers preparing a Korean adult-only game rating application, including required materials, review timing, and store integration.

A practical guide to GSOK’s game-advertising standards, monitoring process, major compliance risks, and pre-launch review checklist.

The Soul Strike case shows how broad “ad-free” claims can create Korean consumer-protection risk. Learn how KFTC enforcement and GSOK self-regulation apply.